Back to Security Advisories
High 2026-07-22

Go-Toolset:rhel8 Security Update — AlmaLinux 8 (ALSA-2026:10704)

AlmaLinux 8

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…

Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key updat…

Type:
security

Severity:
important

Release date:
2026-07-22

Description:
Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.

Security Fix(es):

* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)
* golang: cmd/compile: no-op interface conversion bypasses overlap checking (CVE-2026-27144)
* cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names (CVE-2026-27140)
* golang: cmd/compile: possible memory corruption after bound check elimination (CVE-2026-27143)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 golang-bin-1.25.9-1.module_el8.10.0+4167+2e2e20dd.aarch64.rpm 243432fb45d1de4a739832049f7b3fc91ea12cecee4a13462c60747fed2d26d8
aarch64 golang-race-1.25.9-1.module_el8.10.0+4167+2e2e20dd.aarch64.rpm 3a793f87bf64ea581d4ad5b69a232fdf8f415785d9eb88ee9c6fc35b5a6f50a9
aarch64 delve-1.25.2-1.module_el8.10.0+4074+24330916.aarch64.rpm 88f630e03417fb2d3eb2d58ecb082b2dc0cec1276445da41571e47d1d3fbfc26
aarch64 golang-1.25.9-1.module_el8.10.0+4167+2e2e20dd.aarch64.rpm b08ff6a8ed466592dcfddd087745dc0cbfc628c66ba5f28378a1a181e742373c
aarch64 go-toolset-1.25.9-1.module_el8.10.0+4167+2e2e20dd.aarch64.rpm f62f718cf01abe3eba417756973b23a0c1475281ef2550ae974a31b9c0a2f7e1
noarch golang-src-1.25.9-1.module_el8.10.0+4167+2e2e20dd.noarch.rpm 08ae020c22d2509223bed3cffc426eb98d2b369b27c2b6990b5360693825784b
noarch golang-misc-1.25.9-1.module_el8.10.0+4167+2e2e20dd.noarch.rpm 4d6748b67bf8d872c7e6561d81bf555ae6ee20910d0abba0b8f17f015f9268ec
noarch golang-tests-1.25.9-1.module_el8.10.0+4167+2e2e20dd.noarch.rpm 98f71b55233dcf12c8e375f80412ed3e74bb41fae719b935f79b51bd2640dcfc
noarch golang-docs-1.25.9-1.module_el8.10.0+4167+2e2e20dd.noarch.rpm c1ea754687e6067b2ed0d6344f04105df290f439f3525dbfdb8a5e7e299bce00
ppc64le delve-1.25.2-1.module_el8.10.0+4074+24330916.ppc64le.rpm 17d4c313ef3d0be4e1327a134976fe78c5a06923d13ce8f0bc7c2c3bf4e71eab
ppc64le golang-bin-1.25.9-1.module_el8.10.0+4167+2e2e20dd.ppc64le.rpm 4943b75a62d683cc94e3f8962921eb34cceabe1115bcb5ceb46f51c88471c385
ppc64le golang-race-1.25.9-1.module_el8.10.0+4167+2e2e20dd.ppc64le.rpm 692c2f62fcf6bf1de7a2973c2a696dbbb353772f0ec0099b3319d6f918e1b2bc
ppc64le go-toolset-1.25.9-1.module_el8.10.0+4167+2e2e20dd.ppc64le.rpm e12febb95ddbafe1085b3f7d841ef7ff3ec4d220e3765204f38c1389c2fcb49e
ppc64le golang-1.25.9-1.module_el8.10.0+4167+2e2e20dd.ppc64le.rpm f318a23766fa700cd1cdc27fef164ca35209cd45234a4911f69ef6d88da9a4e4
s390x golang-bin-1.25.9-1.module_el8.10.0+4167+2e2e20dd.s390x.rpm 0d78287bf3e69364fac5e40376d6ae13cf6d11f551efdaf72b05e238f16138b4
s390x golang-race-1.25.9-1.module_el8.10.0+4167+2e2e20dd.s390x.rpm acbaea1d23c064788ad9934154a80f42b1547ea344bbc71e73bf277e12a9cd75
s390x golang-1.25.9-1.module_el8.10.0+4167+2e2e20dd.s390x.rpm d0894c575d5f3e8691408303fb4a574a265fbb6ad0e8a3a52b62670141ea56fd
s390x go-toolset-1.25.9-1.module_el8.10.0+4167+2e2e20dd.s390x.rpm fdf624d0ce69a414a68cb626951bd7630921f94da6b8c0ffe18f9028c117cb1f
x86_64 golang-race-1.25.9-1.module_el8.10.0+4167+2e2e20dd.x86_64.rpm 23e1511b327e9a944cf891b70a43ecae9ccabae93d61b2134bb7aebb8b63e1d5
x86_64 go-toolset-1.25.9-1.module_el8.10.0+4167+2e2e20dd.x86_64.rpm 6485e980a85c1fbcde675d9c53f3f792569edf9fb462e288aa1c7871366e9a81
x86_64 golang-1.25.9-1.module_el8.10.0+4167+2e2e20dd.x86_64.rpm 96473c5822f699322306c3f1c83d367e4a47a3b1deddb73af9755365406dc152
x86_64 delve-1.25.2-1.module_el8.10.0+4074+24330916.x86_64.rpm c977ca34ac6c92aabfc6e36e40a42dc248b1c39360b630b3d722e77ddc66e9fb
x86_64 golang-bin-1.25.9-1.module_el8.10.0+4167+2e2e20dd.x86_64.rpm ea68947a6cd5ab47f5d55f7c8d192044495e42bd32c4184f11d68b6e7ff4a937

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.

Check Your System